BlogLocked or open? Which save to pick for your redacted file
Redaction3 min read

Locked or open? Which save to pick for your redacted file

In this post

After you redact, Conseal asks one final question: lock the restorable copy with a passphrase, or leave it open. It looks like a small choice, but it's the security decision of the whole flow. As the app puts it: the redacted file itself is readable by anyone you send it to. What differs is who can bring the hidden text back.

Lock with passphrase
••••••••••••••••••••••
Lock with passphrase

What both saves have in common

Either way you get a redacted document safe to read, plus a bundle that can restore the hidden values later How to restore a redacted document. The hidden information is equally invisible in both. The difference is only what it takes to unlock the bundle.

Locked: only your passphrase brings it back

Turn on Lock with passphrase and Conseal generates a six-word passphrase, like tennis-sugar-portal-able-turf-angel. From that moment those words are the only key to the hidden text.

Two things follow:

••••••••••••••••••••••
Copy passphrase

Write the passphrase down somewhere safe

Conseal never sees it and cannot reset it. That's the point: a passphrase we could recover, someone else could too. But losing the words means losing the ability to restore, permanently.

••••••

Share it separately, if at all

If a colleague needs to restore the file, send the passphrase through a different channel. A bundle and its passphrase in the same email is a locked door with the key taped to it.

Open: anyone with the file can restore it

Leave Lock with passphrase off and the bundle needs no passphrase: whoever has the file can bring every hidden value back in a few clicks.

…-open.zip

Alarming outside your own machine, but it has a real job: files that never leave your workflow. Redacting for your own records or running the Safe AI Workflow on your own computer The Safe AI Workflow, a passphrase protects you from nobody and becomes a step you type all day.

Before you pick: verify

On the same panel, Verify redaction re-checks the output and confirms with a green Verified clean message that your selected items are gone. Run it before saving; it complements your own read-through rather than replacing it.

Verified clean

The rule

Is the file leaving your hands, ever, for any reason? Locked. No exceptions

Staying on your machine, inside your own workflow? Open is fine

Unsure? Pick locked. Over-caution costs you six typed words. Under-caution means someone you emailed a "redacted" file has just un-redacted it.